Techday
This page was machine-translated and may differ from the original. View original

Wind River Studio Security Updates Including Anti-Tamper Protection

Google 우선 소스Published2021.05.24 14:31
Wind River, for building and operating intelligent systems
Star Labs on its cloud native platform
Strengthening IoT infrastructure security with the addition of Titanium Linux.



Security threats are rapidly increasing. Each new device connected presents a potential entry point for cyberattacks. In fact, IoT devices accounted for 32.72% of infections discovered on wireless networks in 2020.

Wind River announced on the 24th that it has added security features to Wind River Studio to help companies meet stringent cybersecurity and anti-tamper requirements and add safety to the development, deployment, and operation of devices and systems.
▲ Wind River

Industries that rely heavily on software and intelligent systems must address security at every stage of the intelligent systems lifecycle. Wind River Studio is a cloud-native platform for developing, building, operating, and servicing intelligent systems.

Developed by Star Labs, Wind River's technology protection and cybersecurity group, Wind River Titanium Linux offers powerful Linux system hardening and security features, making it suitable for deployment on production Linux systems. Key features of Titanium Linux include secure boot, anti-tamper protection, and simplified creation of mandatory access control (MAC) policies.

Titanium Linux security control features are mapped to major IoT security guidelines, including the NIST IoT Cybersecurity Initiative, the OWASP IoT Security Project, the IoT Security Foundation Protocol, the EU Cybersecurity Agency Guidelines, ETSI, and the GSMA.

Titanium Linux, designed using a threat model that assumes an attacker will gain administrative access to the system, maintains the integrity and confidentiality of critical applications, data, and configurations. It hardens the kernel against attacks and applies MAC to customer applications and data. Even if an attacker exploits the system to gain administrative access, they cannot extract or maliciously modify sensitive data or code.

Wind River Studio uses industry-leading code scanning and analysis tools to help prevent vulnerable code from being released unexpectedly. These features include code coverage analysis, static analysis, rapid in-depth code inspection, and secure container management. Mitigate man-in-the-middle attacks that expose customer, device, and business-sensitive data with cloud and device attestation based on X.509 certificates and confidential storage.

By hardening the Linux kernel, Wind River prevents tampering and reverse engineering attacks targeting the Linux kernel, sensitive data, and critical applications. These include stack overflows, heap overflows, free memory zeroing, and kernel overwrites. The hardened kernel also limits injection attacks through Kernel Address Space Layout Randomization (KASLR) and hardware isolation to prevent kernel memory modification.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자